CVE-2023-46294: Teledyne Flir m300

Low severity, CVSS 3.4. EPSS: 0.1% chance of exploitation in the next 30 days.

An issue was discovered in Teledyne FLIR M300 2.00-19. User account passwords are encrypted locally, and can be decrypted to cleartext passwords using the utility umSetup. This utility requires root permissions to execute.

Affected products

  • Teledyne Flir m300: up to and including 2.00-38

Published 2024-05-01. Last modified 2026-06-17.